LWN.net Logo

tinymce-spellchecker: code execution

Package(s):tinymce-spellchecker CVE #(s):CVE-2012-6112
Created:February 4, 2013 Updated:February 6, 2013
Description: From the Red Hat bugzilla:

A security flaw was found in the way Google spellchecker of TinyMCE spellchecker plugin sanitized content of $lang and $str arguments from presence of control characters when checking for matches. A remote attacker could provide a specially-crafted string, to be checked by the TinyMCE spellchecker plugin that, when processed, could lead to arbitrary code execution with the privileges of the user running the TinyMCE spellchecker plugin.

Alerts:
Fedora FEDORA-2013-1371 2013-02-03
Fedora FEDORA-2013-1341 2013-02-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds